CVE Tools

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Rapid7 BlogBy Jonah Burgess4 min read

Reported exploitedPeopleSoft Enterprise PeopleToolsShinyHuntersUpdates Environment Management

Our summary

Oracle has released an out-of-band fix for CVE-2026-35273, a critical remote code execution issue in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools, affecting PeopleTools versions 8.61 and 8.62. Security researchers report the flaw was exploited in the wild as a zero-day prior to Oracle’s June 10, 2026 advisory, with targeting observed from May 27 through June 9, 2026. This matters because attackers leveraged the weakness to reach PeopleSoft endpoints associated with /PSEMHUB/hub and /PSIGW/HttpListeningConnector, enabling compromise and follow-on activity such as data theft and operational tooling deployment.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

On June 10, 2026, Oracle published a security alert for CVE-2026-35273">CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of 9.8 and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has classified the underlying flaw as a server-side request forgery (CWE-918). PeopleTools versions 8.61 and 8.62 are affected.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store